<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Stealing Pictures with Picasa</title>
	<atom:link href="http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/feed/" rel="self" type="application/rss+xml" />
	<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=stealing-pictures-with-picasa</link>
	<description>Thoughts on Security in an Uncivilized World…</description>
	<lastBuildDate>Fri, 27 Apr 2012 13:53:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Ryan Naraine&#8217;s Zero Day mobile edition</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-223</link>
		<dc:creator>Ryan Naraine&#8217;s Zero Day mobile edition</dc:creator>
		<pubDate>Sat, 24 Nov 2007 02:18:54 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-223</guid>
		<description>[...] Unfortunately, URIs are also accessible to attackers through cross-site scripting (XSS), so an attacker can XSS a Picasa user, load Flash which doesn’t do DNS pinning (this JUST missed our list), and then steal the user’s images without any interaction or confirmation. [...]</description>
		<content:encoded><![CDATA[<p>[...] Unfortunately, URIs are also accessible to attackers through cross-site scripting (XSS), so an attacker can XSS a Picasa user, load Flash which doesn’t do DNS pinning (this JUST missed our list), and then steal the user’s images without any interaction or confirmation. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-208</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Mon, 29 Oct 2007 17:58:16 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-208</guid>
		<description>Hey Nate.. we met at San Diego airport and talked for a bit. We were both headed to Phoenix. Anyways, I couldn&#039;t find an email address and I didn&#039;t want to go &quot;searching&quot; for one, so I thought I&#039;d post a comment here and hope you would respond to the email address I left. You can delete this comment</description>
		<content:encoded><![CDATA[<p>Hey Nate.. we met at San Diego airport and talked for a bit. We were both headed to Phoenix. Anyways, I couldn&#8217;t find an email address and I didn&#8217;t want to go &#8220;searching&#8221; for one, so I thought I&#8217;d post a comment here and hope you would respond to the email address I left. You can delete this comment</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Info World &#187; Blog Archive &#187; Microsoft bows to criticism, will fix Window&#8217;s URI security flaw</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-196</link>
		<dc:creator>Info World &#187; Blog Archive &#187; Microsoft bows to criticism, will fix Window&#8217;s URI security flaw</dc:creator>
		<pubDate>Thu, 11 Oct 2007 17:47:19 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-196</guid>
		<description>[...] example, it would be impossible for Microsoft to fix a recent Picasa flaw discovered by McFeters and Researcher Billy Rios.&#160;&quot;The Picasa flaw is based on the [...]</description>
		<content:encoded><![CDATA[<p>[...] example, it would be impossible for Microsoft to fix a recent Picasa flaw discovered by McFeters and Researcher Billy Rios.&#160;&quot;The Picasa flaw is based on the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Info World &#187; Blog Archive &#187; Microsoft to fix Window&#8217;s URI security flaw after criticism</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-195</link>
		<dc:creator>Info World &#187; Blog Archive &#187; Microsoft to fix Window&#8217;s URI security flaw after criticism</dc:creator>
		<pubDate>Thu, 11 Oct 2007 11:15:07 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-195</guid>
		<description>[...] example, it would be impossible for Microsoft to fix a recent Picasa flaw discovered by McFeters and Researcher Billy Rios.&#160;&quot;The Picasa flaw is based on the [...]</description>
		<content:encoded><![CDATA[<p>[...] example, it would be impossible for Microsoft to fix a recent Picasa flaw discovered by McFeters and Researcher Billy Rios.&#160;&quot;The Picasa flaw is based on the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: A rough week for Google security &#8212; Security Bytes</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-180</link>
		<dc:creator>A rough week for Google security &#8212; Security Bytes</dc:creator>
		<pubDate>Fri, 28 Sep 2007 00:12:15 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-180</guid>
		<description>[...] A Picasa exploit discovered by researchers Billy Rios and Nate McFeters that leverages a combination of XSS, cross [...]</description>
		<content:encoded><![CDATA[<p>[...] A Picasa exploit discovered by researchers Billy Rios and Nate McFeters that leverages a combination of XSS, cross [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nuove vulnerabilità per i servizi Google &#171; APNIBI blog</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-175</link>
		<dc:creator>Nuove vulnerabilità per i servizi Google &#171; APNIBI blog</dc:creator>
		<pubDate>Wed, 26 Sep 2007 15:02:20 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-175</guid>
		<description>[...] scripting bug affligge invece il servizio aziendale Google Search Appliance mentre Google Picasa risulta essere vulnerabile ad un exploit in grado di permettere ad un cracker di prelevare delle immagini [...]</description>
		<content:encoded><![CDATA[<p>[...] scripting bug affligge invece il servizio aziendale Google Search Appliance mentre Google Picasa risulta essere vulnerabile ad un exploit in grado di permettere ad un cracker di prelevare delle immagini [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rcarter</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-172</link>
		<dc:creator>rcarter</dc:creator>
		<pubDate>Wed, 26 Sep 2007 14:21:34 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-172</guid>
		<description>yeah, i&#039;m pretty happy with how it turned out too. the PoC is finally functioning correctly. the thing that was the toughest to get working reliably was the dns rebinding/anti-dns pinning. from everything i&#039;ve read, flash does dns binding and *should* respect the ttl it receives but doesn&#039;t seem to. by comparison the rest was pretty easy.</description>
		<content:encoded><![CDATA[<p>yeah, i&#8217;m pretty happy with how it turned out too. the PoC is finally functioning correctly. the thing that was the toughest to get working reliably was the dns rebinding/anti-dns pinning. from everything i&#8217;ve read, flash does dns binding and *should* respect the ttl it receives but doesn&#8217;t seem to. by comparison the rest was pretty easy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan McFeters</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-166</link>
		<dc:creator>Nathan McFeters</dc:creator>
		<pubDate>Wed, 26 Sep 2007 02:34:29 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-166</guid>
		<description>Actually sjovan, there&#039;s a high likelihood this is vulnerable in Nix too, or at the very least attacks like it.  I&#039;ve mentioned numerous times now that *Nix has registered URI&#039;s as well.

This is one of my favorite attacks that we&#039;ve pulled off.  Lot&#039;s of dynamic pieces.</description>
		<content:encoded><![CDATA[<p>Actually sjovan, there&#8217;s a high likelihood this is vulnerable in Nix too, or at the very least attacks like it.  I&#8217;ve mentioned numerous times now that *Nix has registered URI&#8217;s as well.</p>
<p>This is one of my favorite attacks that we&#8217;ve pulled off.  Lot&#8217;s of dynamic pieces.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sjovan</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-164</link>
		<dc:creator>sjovan</dc:creator>
		<pubDate>Tue, 25 Sep 2007 22:59:24 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-164</guid>
		<description>and then you install linux and stop bothering about stuff like this. good application btw :)</description>
		<content:encoded><![CDATA[<p>and then you install linux and stop bothering about stuff like this. good application btw <img src='http://xs-sniper.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awesome AnDrEw</title>
		<link>http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/comment-page-1/#comment-163</link>
		<dc:creator>Awesome AnDrEw</dc:creator>
		<pubDate>Tue, 25 Sep 2007 22:05:02 +0000</pubDate>
		<guid isPermaLink="false">http://xs-sniper.com/blog/2007/09/24/stealing-pictures-with-picasa/#comment-163</guid>
		<description>It is way more work than I could say I would ever think of doing, but the proof of concept was very nice work. I love how you always tie everything together like that.</description>
		<content:encoded><![CDATA[<p>It is way more work than I could say I would ever think of doing, but the proof of concept was very nice work. I love how you always tie everything together like that.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: xs-sniper.com @ 2012-05-16 22:00:31 -->
